US2025350611A1PendingUtilityA1

System, method, and computer program for application programming interface (api) security

Assignee: AMDOCS DEVELOPMENT LTDPriority: May 9, 2024Filed: May 9, 2024Published: Nov 13, 2025
Est. expiryMay 9, 2044(~17.8 yrs left)· nominal 20-yr term from priority
H04L 63/1441G06F 21/554H04L 63/1416H04L 63/0245G06N 20/00
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

As described herein, a system, method, and computer program are provided for securing a network whose capabilities are accessible by external applications via an API. A request for one or more capabilities of a network is received from an application by an API Gateway of a platform that interfaces the network. Information associated with the request is input to a machine learning model to cause the machine learning model to predict whether the request is at least potentially malicious. The request is prevented from being sent to the network when the machine learning model predicts that the request is at least potentially malicious. The request is sent to the network when the machine learning model predicts that the request is not at least potentially malicious.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A non-transitory computer-readable media storing computer instructions which when executed by one or more processors of a device cause the device to:
 receive, from an application by an application programming interface (API) of a platform that interfaces a network, a request for one or more capabilities of the network;   input information associated with the request to a machine learning model to cause the machine learning model to predict whether the request is at least potentially malicious;   prevent the request from being sent to the network when the machine learning model predicts that the request is at least potentially malicious; and   send the request to the network when the machine learning model predicts that the request is not at least potentially malicious.   
     
     
         2 . The non-transitory computer-readable of  claim 1 , wherein the network is provided by a communication service provider and wherein the application is provided by a third party to the communication service provider. 
     
     
         3 . The non-transitory computer-readable of  claim 2 , wherein the API exposes capabilities of the network to third party applications. 
     
     
         4 . The non-transitory computer-readable of  claim 1 , wherein the capabilities of the network comprise network services, network functions, network information, and network resources. 
     
     
         5 . The non-transitory computer-readable of  claim 1 , wherein the request is to change a behavior of the network. 
     
     
         6 . The non-transitory computer-readable of  claim 1 , wherein the request is for information relating to a subscriber of the network. 
     
     
         7 . The non-transitory computer-readable of  claim 1 , wherein the request is for information relating to the network. 
     
     
         8 . The non-transitory computer-readable of  claim 1 , wherein the information input to the machine learning model includes the request and metadata associated with the request. 
     
     
         9 . The non-transitory computer-readable of  claim 8 , wherein the metadata includes an internet protocol (IP) address of a source of the request. 
     
     
         10 . The non-transitory computer-readable of  claim 8 , wherein the metadata includes hypertext transfer protocol (HTPP) headers included with the request. 
     
     
         11 . The non-transitory computer-readable of  claim 1 , wherein preventing the request further includes preventing any response to the request from being sent to the application. 
     
     
         12 . The non-transitory computer-readable of  claim 1 , wherein preventing the request further includes sending an empty response to the application. 
     
     
         13 . The non-transitory computer-readable of  claim 1 , wherein preventing the request further includes sending an error message to the application. 
     
     
         14 . The non-transitory computer-readable of  claim 1 , wherein sending the request includes sending the request to the network via a network exposure function (NEF) of the platform. 
     
     
         15 . The non-transitory computer-readable of  claim 1 , wherein the device is further caused to:
 receive a response to the request from the network, when the request is sent to the network.   
     
     
         16 . The non-transitory computer-readable of  claim 15 , wherein the device is further caused to:
 send the response to the application.   
     
     
         17 . The non-transitory computer-readable of  claim 1 , wherein the machine learning model is trained to recognize changes in behavior of the application. 
     
     
         18 . The non-transitory computer-readable of  claim 1 , wherein the machine learning model is trained to recognize anomalies in requests received by the API. 
     
     
         19 . A method, comprising:
 at a computer system:   receiving, from an application by an application programming interface (API) of a platform that interfaces a network, a request for one or more capabilities of the network;   inputting information associated with the request to a machine learning model to cause the machine learning model to predict whether the request is at least potentially malicious;   preventing the request from being sent to the network when the machine learning model predicts that the request is at least potentially malicious; and   sending the request to the network when the machine learning model predicts that the request is not at least potentially malicious.   
     
     
         20 . A system, comprising:
 a non-transitory memory storing instructions; and   one or more processors in communication with the non-transitory memory that execute the instructions to:   receive, from an application by an application programming interface (API) of a platform that interfaces a network, a request for one or more capabilities of the network;   input information associated with the request to a machine learning model to cause the machine learning model to predict whether the request is at least potentially malicious;   prevent the request from being sent to the network when the machine learning model predicts that the request is at least potentially malicious; and   send the request to the network when the machine learning model predicts that the request is not at least potentially malicious.

Join the waitlist — get patent alerts

Track US2025350611A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.